Creation of a trusted data packet

The method of creating and storing trustworthy data packets by linking trustworthiness information with data units addresses the lack of robust trust assessment in existing data transmission methods, enhancing data security and integrity, especially in Zero Trust environments.

WO2025108715A1PCT designated stage expired Publication Date: 2025-05-30SIEMENS AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/081427
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-20
Filing Date
2024-11-07
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing data transmission methods lack a robust mechanism to assess and store the trustworthiness of data sources, which is critical in ensuring the security and integrity of data across organizational boundaries, especially in a Zero Trust security environment.

Method used

A method for creating and storing a trustworthy data packet by receiving data units and associated integrity information from a data source, determining trustworthiness information based on this integrity information, and linking this information with the data units for storage.

Benefits of technology

This approach enables the explicit assessment and storage of trustworthiness information, allowing for more secure data handling and processing, even in Zero Trust environments, by decoupling trust assessment from network zones and enabling further processing and evaluation of data trustworthiness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024081427_30052025_PF_FP_ABST
    Figure EP2024081427_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for storing a trusted data packet (32, 32B), comprising the steps of: - receiving (S1) the following from a data source (1): ○ at least one data unit (32), ○ at least one item of integrity information (32A) of the data source (1), which is assigned to the at least one data unit (32), - determining (S2) an item of trustworthiness information (32B) based on the at least one item of integrity information (32A), - creating (S3) the trusted data packet (32, 32B) by assigning the item of trustworthiness information (32B) to the at least one data unit (32), and - storing (S4) the trusted data packet (32, 32B). The invention furthermore relates to a computer program product, to a computer-readable storage medium and to higher-level system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Creating a trusted data package

[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.

[0004] BACKGROUND OF THE INVENTION

[0005] Field of the invention

[0006] The invention relates to a method for storing a trusted data packet. The invention also relates to a computer program product, a computer-readable medium, and a higher-level system.

[0007] Description of the state of the art

[0008] For Windows, it is known that a zone identifier can be present as meta information for a file, which indicates the origin of the file (Local machine, Local intranet, Trusted sites, Internet, Restricted sites).

[0009] An application can apply different security options depending on this information. This classification implicitly conceals a security concept based on network segmentation. The security level results from the network area in which the source from which a file was downloaded is located. With a Zero Trust security concept, however, the distinction between the network area (intranet, internet) is no longer a decisive criterion. Instead, when a user accesses a file, its legitimacy is checked not only based on the user's access authorization, but also on other criteria, e.g., whether the device meets defined security requirements. As mentioned, it is known that a file contains associated information, in particular that it was downloaded from the internet. Depending on this, an application, e.g., a text editor, can select security settings when opening the file (e.g.,(activate read-only mode). To do this, a zone identifier is stored in an "alternative stream" of the file. The zone identifier can be used to distinguish between the following categories: Local machine, Local intranet, Trusted sites, Internet, Restricted sites.

[0010] It is also known that a security classification (e.g. open, internal, confidential, secret) is contained as meta-information in a file (e.g. in data loss prevention) or can be assigned to a file (e.g. SELinux).

[0011] With a Zero Trust Security concept, it is known that when a user accesses a service, the device compliance information of the device used by the user is also checked.

[0012] Data rooms are also known for exchanging data across organizational boundaries.

[0013] The International Data Space IDS (formerly Industrial Data Space) is known to use a signed token to confirm the trustworthiness of an IDS connector during data transmission between two IDS connectors (“The token is presented by each subsequent outgoing communication message of the connector, so that the communicating connectors also have a means to verify the trustworthiness of their communication partners at any time.”). However, the token information is only used to protect data transmission between IDS connectors. The implicit assumption is that data transmission only takes place between sufficiently trustworthy IDS connectors, i.e., that received data always originates from a sufficiently trustworthy source. In AI learning, a so-called “curriculum learning” is known, in which the order of the learning data is determined depending on its content (see, for example,Petru Soviany, Radu Tudor lonescu, Paolo Rota, Nicu Sebe, “Curriculum Learning: A Survey”) . For example, a learning strategy can be implemented in which the basic cases (fundamentals) are first learned by an AI model before the special cases are learned .

[0014] Digital watermarking of data is a well-known technique. This involves embedding additional information within the data, e.g., in noise signal components (e.g., in audio data, image data, or video data).

[0015] The object of the invention is to provide a solution for improved data transmission in communication networks.

[0016] SUMMARY OF THE INVENTION

[0017] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention will become apparent from the following description and the drawings.

[0018] The invention relates to a method for storing a trustworthy data packet, comprising the steps:

[0019] - Receiving (in particular loading and / or querying) from a data source of: o at least one data unit (or several data units, also referred to as data), o at least one piece of integrity information of the data source which is assigned to the at least one data unit,

[0020] - determining trustworthiness information depending on the at least one piece of integrity information (in particular directly or indirectly (with an intermediate step) from the integrity information)

[0021] - creating the trustworthy data packet by associating the trustworthiness information with the at least one data unit (in particular by linking the trustworthiness information and the at least one data unit), and

[0022] - saving the trusted data packet.

[0023] The present invention therefore proposes, in particular, to determine trustworthiness information of the data source during data transmission, in particular during (i.e. during) the transmission of a file, and to store this information associated with the received and stored data or the received and stored file and / or as part thereof (i.e. in the file system, as an attribute of the file or as an alternative stream of the file, or embedded in the data itself in the form of a digital watermark).

[0024] The at least one piece of data source integrity information is assigned to the at least one data unit. In one embodiment, this is achieved by loading the data unit via an HTTPS connection (e.g., a PDF file), and assigning the data source integrity information to the data unit because it is loaded from the same data source as the data unit (via the same HTTPS connection or via a second HTTPS connection to the same data source).

[0025] The at least one data unit and the at least one piece of integrity information are alternatively part of a raw data packet, whereby the at least one piece of integrity information is assigned to the at least one data unit. The raw data packet can, for example, be designed as an XML data structure, as a JSON data structure, as an archive file (e.g., ZIP, 7z). It is also possible for a raw data packet to be designed such that its elements, ie in particular the at least one data unit and the at least one piece of integrity information of the data source, are transmitted together, for example via the same communication connection (e.g., a TLS, DTLS, HTTP, HTTPS, QUIC communication connection) or via two cryptographically bound communication connections (e.g.,two TLS communication connections that are cryptographically bound by a cryptographic credential, for example by means of a TLS session resumption or by using the same authentication credential to establish the connection).

[0026] The at least one piece of integrity information of the data source is determined in particular:

[0027] - by a runtime health check component of the data source device, e.g. for repeated integrity checks of the firmware and the executed software of the source node at runtime, and / or

[0028] - by a Root of Trust for Measurement of the data source device, which, for example, determines device integrity information during device startup (booting) (e.g. for a Trusted Platform Module of the originating node, ie the data source).

[0029] The integrity information of the data source can be cryptographically protected, for example by a cryptographic checksum, a digital signature, a group signature or by a message authentication code. The integrity information of the data source can be a cryptographically protected attestation created by an attestation module of the data source. The attestation module can be created, for example, as a hardware-based security element or as a trusted execution environment of a processor. The attestation module can also manage the integrity information of the data source in a tamper-proof manner, i.e., store and update it. The data source can be, for example, a file server, a web server, a PubSub server, a content distribution server, a proxy server or a database.In one variant, multiple data sources can be identified from which the data unit is loaded, e.g., a web server (HHTP server) and a proxy server (HTTP proxy). In this case, multiple integrity information items can be identified, each associated with one of the data sources. When creating the trusted data packet, these multiple trust information items can be assigned to them.

[0030] One element of a Zero Trust architecture is that when a user accesses the system, not only is the user authenticated and their access authorization verified, but the trustworthiness of the device they are using is also verified. This verification occurs when accessing a service or application. One aspect of the invention is to assign trustworthiness information to files. This allows files to be assigned trustworthiness information even in a Zero Trust security strategy. Furthermore, this supports a more trustworthy use of data shared across organizational boundaries.

[0031] The invention offers the advantage that the information regarding the trustworthiness of a file is not based on the security zone (Internet, Intranet, etc.), i.e., the network area from which the file would be loaded, as is currently the case with Windows systems, but rather on the explicit trustworthiness assessment of the data source by the recipient. This applies the Zero Trust security concept to the trustworthiness assessment of loaded files. The information is not checked upon access to a service or application, as is currently the case with Zero Trust, but is available after the data has been transferred. This allows this trustworthiness information to be evaluated at a later time when the stored data is further processed.

[0032] Furthermore, it can be evaluated whether a file was loaded from a device that was integer during the file transfer (a managed device considered compliant, Device Integrity Attestation). It can also be evaluated whether the device authenticated itself using strong cryptographic methods during the file transfer. This information is useful, for example, during a migration to post-quantum cryptography, as it can be determined whether a file was loaded using PQ security.

[0033] In a further development of the invention, the data source is designed as: a sender, an originating node (also referred to as a source node), a device as a whole, a sub-area of ​​a device, a protected execution environment (in particular ARM TrustZone, Intel SGX, Confidential Computing), a service, in particular a cloud service and / or a web service, a virtual machine and / or a container.

[0034] In a further development of the invention, the at least one data unit is also assigned:

[0035] - an authentication of a sender of the at least one data unit,

[0036] - authentication of the data source,

[0037] - an authentication certificate, in particular for a cipher suite of a transmission channel used,

[0038] - an authentication of a system superior to the data source, in particular a superior device,

[0039] - at least one file attribute and / or

[0040] - access authorization. The data unit received according to the inventive method and its associated characteristics are queried by the data source, in particular by a device directory system or a device management system, during data transmission.

[0041] Accordingly, the received data unit and its associated characteristics are assigned to the trusted data packet, particularly when the trusted data packet is created.

[0042] In a further development of the invention, at least one data unit is designed as:

[0043] - at least one file,

[0044] - Learning data for artificial intelligence,

[0045] - Test data for artificial intelligence,

[0046] - a software file,

[0047] - a software package,

[0048] - video data,

[0049] - archive data, especially ZIP data,

[0050] - image data or

[0051] - design data,

[0052] Project planning data,

[0053] - Billing data and / or

[0054] - Consumption data .

[0055] If the at least one data unit has several data units, i.e. at least two data units, it can also be referred to as data.

[0056] In a further development of the invention, the at least one integrity information is designed as:

[0057] - Device integrity information,

[0058] - an integrity information of a firmware, software and / or hardware of the data source and / or

[0059] - a cryptographically protected attestation. The at least one piece of integrity information is furthermore designed in particular as:

[0060] Information that the data source is cryptographically authenticated. Furthermore, the authenticated identity or the credential used for authentication, e.g., the authentication certificate or the public authentication key of the data source, can be used. Furthermore, information about the cryptographic algorithms used and the key length, i.e., the cipher suite used for data transmission, can be used. This provides information, for example, about whether a post-quantum-secure cryptographic cipher suite was used for data transmission. Furthermore, the root certificate used to validate the authentication certificate can be used, or the entire certificate path of the authentication certificate can be stored.

[0061] Information about the integrity of the data source (device integrity, software application integrity). This can be confirmed by a cryptographically protected attestation (e.g., a TPM attestation, a Google Play Integrity attestation, or an SGX attestation).

[0062] Information on the security compliance of the data source (e.g. current patch status, virus scanner present and up to date).

[0063] Information on the level of protection of the data source (e.g. whether it is a confidential computing enclave or a trusted execution environment or an open compute system with an operating system accessible at user level, e.g. command line access, or an embedded device with functionality defined by its firmware).

[0064] Information about whether the data source is managed by a device management system, i.e., whether the device is managed by an enterprise device management system. Furthermore, information about which enterprise management system manages the device and whether the device is classified as compliant, i.e., whether it meets the defined device compliance policy, can be used.

[0065] Information about whether the data source has tamper protection to prevent (tamper detection) or to detect physical tampering (tamper response), or whether it is installed in a physically access-protected environment (e.g., a locked, alarm-monitored rack or server room). This information can be retrieved, for example, from a device management system or a device directory service.

[0066] In a further development of the invention, the trustworthiness information is determined by a rule-based analysis of at least one piece of integrity information.

[0067] In a further development of the invention, the method according to the invention comprises the further step:

[0068] Determining at least two preliminary trustworthiness information items from the at least one integrity information item, wherein the trustworthiness information items are created based on the at least two preliminary trustworthiness information items.

[0069] In this variant, during the reception (in particular loading and / or querying) of the at least one data unit, a preliminary trustworthiness information (from the integrity information of the data source) is determined several times.

[0070] In this case, multiple pieces of integrity information from the data source and / or multiple pieces of preliminary trustworthiness information can be checked for consistency before the trustworthiness information is determined from it and, in particular, stored in an extended attribute of the trusted data package. This is particularly advantageous for large file transfers, especially when the file is a large software package, a large video file, an archive file, e.g., a ZIP file, with a large amount of image data or design data, or an archive file with extensive learning data for training an AI model.

[0071] In a further development of the invention, the receiving (in particular the loading) of the at least one data unit from the data source takes place within the framework of a data transmission, wherein the data transmission takes place during a time period, wherein the time period has a start and an end time, wherein the determination of the at least two preliminary trustworthiness information items takes place at the start and / or at the end time.

[0072] In a further development of the invention, the trustworthiness information is assigned to the at least one data unit by: linking the trustworthiness information and the at least one data unit, forming an extended attribute, preferably in an "alternative stream" of the at least one file unit, wherein the extended attribute is assigned to the trustworthy data packet, in particular is a component of the trustworthy data packet, embedding the trustworthiness information in the at least one data unit in the form of a digital watermark.

[0073] The trusted data package can also be executed as a trusted file system that contains the trustworthiness information and the at least one data unit. The extended attribute provides trustworthiness information from the data source for the at least one data unit, which relates to the time at which the at least one data unit was received / loaded from the data source.

[0074] In a further development of the invention, the trustworthiness information is designed as: the at least one piece of integrity information of the data source in the raw data format, a categorization, a classification and / or a security classification.

[0075] In particular, the raw information (integrity information of the data source) is stored as trustworthiness information.

[0076] Alternatively or additionally, trustworthiness information is determined / created, which indicates a categorization, in particular a rating, in particular a security rating. The categorization is carried out in particular based on a predeterminable set of rules. The categorization has categories. Categories are in particular "low trust", "medium trust", "high trust" and / or "untrusted", "enterprise trust", "OT trust", "cloud provider trust".

[0077] In a further development of the invention, the trustworthy data packet is provided so that access to the trustworthy data packet occurs depending on the trustworthiness information.

[0078] In a further development of the invention, accessing includes:

[0079] Processing, filtering, checking and / or using.

[0080] The invention enables an application on the target node (receiver of the at least one data unit) which is executed by an app execution environment (RTE, Runtime Environment) and / or the app execution environment itself to adapt the data processing depending on access to the stored data or to the stored file at a later point in time (e.g. discard data, subject it to a plausibility check, subject it to data filtering, subject it to a malware check, or use it without being checked).

[0081] For example, when training an AI model, only data that comes from a source recognized as trustworthy can be used as learning data.

[0082] It is also possible to sort the order of data when learning an AI model based on its trustworthiness (e.g., learning data from a trusted source first). This is called "curriculum learning" of the AI ​​model, with trustworthiness being used as an ordering criterion for the learning data.

[0083] Furthermore, it is possible that billing data or consumption data will only be processed automatically if the data originates from a data source for which the device integrity was positively confirmed at the time of data transmission.

[0084] The invention also comprises a computer program product comprising a computer program, wherein the computer program can be loaded into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit. The invention also comprises a computer-readable medium on which a computer program is stored, wherein the computer program can be loaded into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit.

[0085] The invention also includes a system comprising:

[0086] - a computer program product according to claim 13 and / or

[0087] - a computer-readable medium according to claim 1 .

[0088] BRIEF DESCRIPTION OF THE DRAWINGS

[0089] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.

[0090] It shows

[0091] Fig. 1 is a flow diagram of the method according to the invention,

[0092] Fig. 2 is a schematic representation of a system according to the invention.

[0093] DETAILED DESCRIPTION OF THE INVENTION

[0094] Fig. 1 shows a flow diagram of the inventive method for storing a trustworthy data packet, with the steps:

[0095] Step S1: Receiving from a data source: o at least one data unit, o at least one piece of integrity information of the data source, wherein the integrity information is associated with the at least one data unit,

[0096] Step S2: Determining trustworthiness information as a function of the at least one piece of integrity information, Step S3: Creating the trustworthy data packet by associating the trustworthiness information with the at least one data unit, and Step S4: Storing the trustworthy data packet.

[0097] Fig. 2 shows an embodiment in which data 32 from a data storage unit 13, e.g. a file 32, is transmitted from an originating node 1 (also referred to as source node 1, in particular a first device 1) to a destination node 2 (destination node 2) via an authenticated, cryptographically protected communication channel 31 (e.g. TLS, DTLS; QUIC) within a communication network 3. The originating node 1 is connected to the communication channel 31 by a first connection 12. The destination node 2 is connected to the communication channel 31 by a second connection 21.

[0098] In addition to the data 32 and its authentication information 11 (also referred to as a "Device Authentication Certificate" 11 and created by an attestation unit 14), the originating node 1 provides trustworthiness information 32A in the form of a cryptographically protected integrity confirmation 32A (also referred to as a "Device Integrity Attestation" 32A). The integrity confirmation 32A includes, in particular, an ID of the originating node 1. In particular, the integrity confirmation 32A is cryptographically protected by a signature.

[0099] The integrity information 32A can be determined by a runtime health check component 16 of the first device 1, e.g., for repeated integrity checks of the firmware and the executed software of the source node 1 at runtime, and / or by a root of trust for measurement 15, which, e.g., determines device integrity information 32A (e.g., for a Trusted Platform Module of the source node 1) during device startup (booting). The target node 2, in particular a second device 2, stores the received data 32 in a file system 23. In addition to the actual data 32 and generally known file attributes such as owner and access rights, trustworthiness information 32B of the data source 1, e.g., the source node 1, is stored as a file attribute or as an "alternative stream" of the file 32 and is previously determined by a unit 22 for determining the trustworthiness information 32B.

[0100] Alternatively or additionally, the trustworthiness information 32B can be embedded in the data 32 of the file in the form of a digital watermark 32B.

[0101] This trustworthiness information 32B of the data source 1 can be determined depending on the provided device integrity attestation 32A of the originating node 1 (e.g., untrusted, enterprise-trust, OT-trust, cloud-provider-trust). However, it is also possible to store the obtained raw integrity information 32A.

[0102] In addition to the device integrity attestation 32A, information for authenticating the source node 1, in particular its authentication certificate 11, for the cipher suite of the transmission channel 31 used to transmit the data 32, or information about the source node 1, which the destination node 2 can query from a device directory system 34 or from a device management system 33 during the transmission of the data, can also be used.

[0103] An application 24 (app 24) on the target node 2, which is executed by an app execution environment 25 (RTE 25, Runtime Environment 25), and / or the app execution environment 25 itself, can adapt security options when accessing a stored file 32 depending on its trustworthiness information 32B of the data source. Although the invention has been illustrated and described in detail by the embodiments, the invention is not limited by the disclosed examples, and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.

Claims

Patent claims 1. A method for storing a trusted data packet (32, 32B), comprising the steps of: - Receiving (S1) from a data source (1) of: o at least one data unit (32), o at least one piece of integrity information (32A) of the data source (1) which is associated with the at least one data unit (32), - determining at least two preliminary trustworthiness information items from the at least one integrity information item (32A), - determining (S2) a trustworthiness information item (32B) as a function of the at least one piece of integrity information item (32A), wherein the creation of the trustworthiness information item (32B) is based on the at least two preliminary pieces of trustworthiness information item, wherein the determination of the trustworthiness information item (32B) is carried out by a rule-based analysis of the at least one piece of integrity information item (32A), - creating (S3) the trustworthy data packet (32, 32B) by assigning the trustworthiness information (32B) to the at least one data unit (32), and - storing (S4) the trusted data packet (32, 32B).

2. The method according to claim 1, wherein the data source (1) is configured as: a sender, an originating node, a device as a whole, a sub-area of ​​a device, a protected execution environment, a service, a virtual machine and / or a container.

3. Method according to one of the preceding claims, wherein the at least one data unit is also assigned: - an authentication (11) of a sender (1) of the at least one data unit, - authentication of the data source (32, 32A), - an authentication certificate (11) , - an authentication (11) of a system higher than the data source (1), in particular a higher-level device, - at least one file attribute and / or - an access authorization.

4. Method according to one of the preceding claims, wherein the at least one data unit (32) is designed as: - at least one file, - Learning data for artificial intelligence, - Test data for artificial intelligence, - a software file, - a software package, - video data, - archive data, especially ZIP data, - image data or - design data, - Billing data and / or - Consumption data.

5. Method according to one of the preceding claims, wherein the at least one integrity information item (32A) is configured as: - Device integrity information, - an integrity information of a firmware, software and / or hardware of the data source and / or - a cryptographically protected attestation.

6. Method according to one of the preceding claims, wherein the receiving of the at least one data unit (32) from the data source (1) takes place within the framework of a data transmission, wherein the data transmission takes place during a time period, wherein the time period has a start and an end time, wherein the determination of the at least two preliminary trustworthiness information items takes place at the start and / or at the end time.

7. The method according to any one of the preceding claims, wherein the assignment of the trustworthiness information (32B) to the at least one data unit (32) is carried out by: linking the trustworthiness information (32B) and the at least one data unit (32), forming an extended attribute, wherein the extended attribute is assigned to the trustworthy data packet (32, 32B), embedding the trustworthiness information (32B) in the at least one data unit (32) in the form of a digital watermark.

8. The method according to any one of the preceding claims, wherein the trustworthiness information (32B) is configured as: the at least one piece of integrity information (32A) of the data source (1) in raw data format, a categorization, a classification and / or a security classification.

9. Method according to one of the preceding claims, wherein the trustworthy data packet (32, 32B) is provided so that access to the trustworthy data packet (32, 32B) takes place depending on the trustworthiness information (32B).

10. The method of claim 9, wherein accessing: Processing, filtering, checking plausibility and / or using includes .

11. Computer program product comprising a computer program, wherein the computer program is loadable into a memory device of a computing unit, wherein the steps of a method according to one of claims 1 to 10 are carried out with the computer program when the computer program is executed on the computing unit.

12. A computer-readable medium on which a computer program is stored, the computer program being loadable into a memory device of a computing unit, the steps of a method according to any one of claims 1 to 10 being carried out with the computer program when the computer program is executed on the computing unit. 13 . System comprising: - a computer program product according to claim 11 and / or - a computer-readable medium according to claim 12 .

Citation Information

Patent Citations

  • Content usage monitor

    US20110035589A1

  • Authenticating time sources using attestation-based methods

    US20200322075A1

  • Communication system, communication device on transmission side and reception or transfer side, method for data communication and data transmission program

    WO2010024379A1